
Livemesh Addons by Elementor Security & Risk Analysis
wordpress.org/plugins/addons-for-elementorElementor Addons that saves time with multiple ready-to-use drag and drop styles for 30+ essential widgets built for Elementor page builder.
Is Livemesh Addons by Elementor Safe to Use in 2026?
High Risk
Score 30/100Livemesh Addons by Elementor carries significant security risk with 22 known CVEs, 3 still unpatched. Consider switching to a maintained alternative.
The 'addons-for-elementor' plugin version 9.0 presents a mixed security posture. While it exhibits some positive security practices, such as 100% output escaping and no file operations or external HTTP requests, significant concerns remain. The plugin has a history of numerous vulnerabilities, totaling 18 known CVEs, with 2 high and 16 medium severity issues. This extensive history, especially the prevalence of path traversal, cross-site scripting, and missing authorization, suggests recurring or systemic security weaknesses within the codebase that have been difficult to fully remediate.
The static analysis reveals a somewhat limited but concerning attack surface. Out of 2 total entry points, 1 AJAX handler lacks authentication checks, which is a critical oversight. While the plugin has nonce and capability checks, their limited application on entry points is a weakness. The SQL query practices are inconsistent, with only 33% using prepared statements, potentially leaving the plugin vulnerable to SQL injection if the remaining queries handle user-supplied data improperly. The absence of taint analysis results might indicate a limited scope of the analysis or that the tool couldn't identify complex data flows, which should not be mistaken for an absence of risk. The bundled Freemius library at v1.0 is also a potential concern if it's an outdated version with known vulnerabilities.
In conclusion, despite some good security practices, the plugin's extensive vulnerability history, combined with a critical unauthenticated AJAX handler and inconsistent SQL preparation, creates a significant risk. The recurring types of vulnerabilities suggest a need for more rigorous code auditing and a more robust approach to security across all entry points. The lack of currently unpatched CVEs is a positive, but the overall risk profile remains elevated due to the historical patterns and identified code weaknesses.
Key Concerns
- Unauthenticated AJAX handler detected
- Only 33% of SQL queries use prepared statements
- 18 known CVEs with multiple high/medium severity
- Bundled Freemius v1.0 may be outdated
Livemesh Addons by Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
22 total CVEs
Livemesh Addons by Elementor <= 9.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via Plugin Settings
Livemesh Addons by Elementor <= 9.0 - Authenticated (Contributor+) Local File Inclusion via Widget Template Parameter
Livemesh Addons for Elementor <= 9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Livemesh Addons for Elementor <= 8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Elementor Addons by Livemesh <= 8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via piechart_settings Parameter
Elementor Addons by Livemesh <= 8.4 - Authenticated (Contributor+) Limited Local File Inclusion via Widgets
Elementor Addons by Livemesh <= 8.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Marquee Text Widget, Testimonials Widget, and Testimonial Slider Widgets
Elementor Addons by Livemesh <= 8.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Various Widgets
Elementor Addons by Livemesh <= 8.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Grid
Elementor Addons by Livemesh <= 8.3.6 - Authenticated(Contributor+) Stored Cross-Site Scripting via widget _id attribute
Elementor Addons by Livemesh <= 8.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Display Name
Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Multislider Widget
Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Slider Widget
Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Carousel Widget
Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Members Widget
Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text Widget
Livemesh Addons for Elementor <= 8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via animated_text_class
Elementor Addons by Livemesh <= 8.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Elementor Addons by Livemesh <= 8.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Livemesh Addons for Elementor <= 7.2.3 - Authenticated (Admin+) Stored Cross-Site Scripting
Livemesh Addons for Elementor <= 6.7.1- Contributor+ Stored Cross-Site Scripting
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Livemesh Addons by Elementor Release Timeline
Livemesh Addons by Elementor Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Livemesh Addons by Elementor Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 28
Maintenance & Trust
Livemesh Addons by Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Livemesh Addons by Elementor Alternatives
HT Mega Addons for Elementor – Elementor Widgets & Template Builder
ht-mega-for-elementor
Elementor addon offering 135+ widgets — Mega Menu, Ready Templates, Page Builder, Slider, Gallery, Post Grid, AI Writer & more.
LA-Studio Element Kit for Elementor
lastudio-element-kit
The advanced addons for Elementor
Move Addons for Elementor
move-addons
Move Addons is a WordPress plugin for Elementor page builder, is a powerful tool that helps you to make almost every possible customization to your we …
WPBITS Addons For Elementor Page Builder
wpbits-addons-for-elementor
Addons for Elementor Page Builder.
Easy Elementor Addons – Addons Pack for Elementor Page Builder
easy-elementor-addons
Level up with Easy Elementor Addons – adds powerful widgets and sleek design tools to your favorite Elementor page builder.
Livemesh Addons by Elementor Developer Profile
8 plugins · 80K total installs
How We Detect Livemesh Addons by Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/addons-for-elementor/assets/css/livemesh-el-addons.css/wp-content/plugins/addons-for-elementor/assets/js/livemesh-el-addons.js/wp-content/plugins/addons-for-elementor/includes/widgets/premium/assets/css/premium-addons.css/wp-content/plugins/addons-for-elementor/includes/widgets/premium/assets/js/premium-addons.js/wp-content/plugins/addons-for-elementor/freemius/start.phpaddons-for-elementor/assets/css/livemesh-el-addons.css?ver=addons-for-elementor/assets/js/livemesh-el-addons.js?ver=addons-for-elementor/includes/widgets/premium/assets/css/premium-addons.css?ver=addons-for-elementor/includes/widgets/premium/assets/js/premium-addons.js?ver=HTML / DOM Fingerprints
lae-info-box-iconlivemesh-el-addonsdata-lae-noncewindow.lae_fs